VPN IPSec IKEv2 Access from internet

Hello everyone,
I bought my first mikrotik few days ago. Because of my small knowledge about RouterOS and network structures I can’t get over VPN configuration. At the moment I can connect to my VPN from my LAN network but I cannot manage to do it from outside - e.g. my phone. Secondly I tried to set up my phone as a hotspot and connect computer through this hotspot to my vpn (with exactly the same configuration when I’m in LAN) but I cannot do it also. It seems like I have firewall configured improper way.

My configuration is almost step by step by this film: https://www.youtube.com/watch?v=fQokeBcrjdc I tried also change it a bit with mikrotik wiki but It seems like IPSec configuration isn’t responsible for this fault.

I opened 4500, 500, 1701 ports and IPSec-esp protocol - it didn’t help at all. Added forward traffic from ETh1-WAN - same problem.

My hardware is: RB4011iGS+5HacQ2HnD
Firmware Type al2
Factory Firmware 6.44.4
Current Firmware 6.45.7
Upgrade Firmware 6.45.7

LAN: 192.168.2.0
VPN 10.0.88.0

In attachments you can find three logs for: my phone stronswan connection, connection via hotspot and connection from my LAN.

I would be grateful for any help.

Best regards,
misiek
ipsecike2log.txt (53.1 KB)

I still didn’t figure out how to make my VPN works from internet. If anyone ould help I would be grateful.

Try this here: https://wiki.mikrotik.com/wiki/Manual:IP/IPsec#Road_Warrior_setup_using_IKEv2_with_RSA_authentication